Splunk Search

Why are we seeing a "Server Error" message after each search, login attempt, etc. on our search head and indexer?

nivedita_viswan
Path Finder

We have 1 indexer and 1 search head in our Splunk environment.
Since this morning, after every search is run, a 'Server Error' message is seen, both on the search head, as well as the indexer. The search continues to run and even completes without any real error. However, this message always appears when the search completes/ is paused/ finalized.

Even during a failed login attempt (incorrect credentials), the 'Server Error' message is seen. This message is also seen when scheduled searches and alerts are run.

What could be the reason for the 'Server Error' message? I skimmed through the logs, and there is nothing unusual there.

0 Karma
1 Solution

nivedita_viswan
Path Finder

I never did figure out what was causing the message. Re-installing my browser fixed the issue though.

View solution in original post

0 Karma

di2esysadmin
Path Finder

Your Splunk user might not have permission to create and update alerts. 

0 Karma

nivedita_viswan
Path Finder

I never did figure out what was causing the message. Re-installing my browser fixed the issue though.

0 Karma

emiller42
Motivator

Might want to pop open your browsers developer console and look to see if there are any errors there. Because Splunk is a RESTful app, there are a bunch of requests going on under the hood, and if one of them fails, you see the generic 'server error' messages.

Hopefully there's a bad HTTP response code attached to a specific endpoint, which you can then chase down in the logs.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...